<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114992#M24062</link>
    <description>&lt;P&gt;on client:&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/bin/splunk start&lt;BR /&gt;
The splunk daemon (splunkd) is already running.    &lt;/P&gt;

&lt;P&gt;on server also is running, i have 230 hosts sending logs on splunk.&lt;BR /&gt;
also in this case i am monitoring /var/log/&lt;BR /&gt;
i think i followed all the instructions.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2014 15:30:18 GMT</pubDate>
    <dc:creator>blebit</dc:creator>
    <dc:date>2014-11-10T15:30:18Z</dc:date>
    <item>
      <title>Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114987#M24057</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;

&lt;P&gt;after installing splunk universal forwarder on linux machine RHEL i have this message after ./splunk list forward-server :&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        None&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        x.x.x.x:9997&lt;BR /&gt;
but i checked firewall and it is ok.&lt;/P&gt;

&lt;P&gt;Connection to x.x.x.x 9997 port [tcp/palace-6] succeeded!&lt;BR /&gt;
But logs are not going on splunk server&lt;BR /&gt;
universalforwarder version: splunkforwarder-6.1.4-233537-linux-2.6-x86_64.rpm&lt;/P&gt;

&lt;P&gt;what might be the problem?&lt;BR /&gt;
thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 14:14:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114987#M24057</guid>
      <dc:creator>blebit</dc:creator>
      <dc:date>2014-11-10T14:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114988#M24058</link>
      <description>&lt;P&gt;Did you enable Receiving on the Splunk Server, which is supposed to get the logs forwarded by UF?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 14:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114988#M24058</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-11-10T14:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114989#M24059</link>
      <description>&lt;P&gt;yes, because i am receiving from other linux hosts&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:00:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114989#M24059</guid>
      <dc:creator>blebit</dc:creator>
      <dc:date>2014-11-10T15:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114990#M24060</link>
      <description>&lt;P&gt;What version is your indexer/heavy forwarder doing the receiving?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114990#M24060</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-11-10T15:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114991#M24061</link>
      <description>&lt;P&gt;Interesting, Just did a UF install. Created some Monitor stanzas in inputs.conf and mentioned server in the outputs.conf. I see the server address after forwards: x.x.x.x. Is the splunkd running on the splunk server &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; (Please don't yell at me for asking this). Reason why i ask, i get forward : none after i intentionally stopped splunkd on Splunk server.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114991#M24061</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-11-10T15:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114992#M24062</link>
      <description>&lt;P&gt;on client:&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/bin/splunk start&lt;BR /&gt;
The splunk daemon (splunkd) is already running.    &lt;/P&gt;

&lt;P&gt;on server also is running, i have 230 hosts sending logs on splunk.&lt;BR /&gt;
also in this case i am monitoring /var/log/&lt;BR /&gt;
i think i followed all the instructions.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114992#M24062</guid>
      <dc:creator>blebit</dc:creator>
      <dc:date>2014-11-10T15:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are logs not being forwarded after installing the universal forwarder on Linux machineRHEL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114993#M24063</link>
      <description>&lt;P&gt;splunk server: 6.1.2 on centOS&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-logs-not-being-forwarded-after-installing-the-universal/m-p/114993#M24063</guid>
      <dc:creator>blebit</dc:creator>
      <dc:date>2014-11-10T15:31:03Z</dc:date>
    </item>
  </channel>
</rss>

